Securelist
New Ransomware Scheme Targets Corporate Printers and BitLocker
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
In June 2026, a series of ransomware attacks were reported in Colombia and Mexico, where attackers exploited misconfigured corporate printers and remote desktop services to encrypt data using BitLocker. The attackers demanded ransoms as low as $3,000, with victims receiving printed ransom notes. The Colombian incident involved an 8 TB storage device containing critical financial data, which was encrypted after the attackers gained control via an exposed RDP service. The affected organizations faced challenges in forensic analysis due to their quick restoration of systems, leading to a loss of evidence. This incident highlights the vulnerabilities associated with open RDP ports and disabled endpoint protection. Similar tactics were observed in the Mexican incident, indicating a growing trend in ransomware targeting corporate infrastructure through unconventional methods.
Key Points: • Ransomware attacks in Colombia and Mexico exploited corporate printers and BitLocker. • Attackers demanded ransoms as low as $3,000, using printed notes to communicate. • Misconfigured RDP services and disabled endpoint protection facilitated the breaches.